Privacy Policy

Updated 2026-10-02

1. Who we are

Lekh is provided by LEKHAPP LLC, 2120 Natoma PL, Manteca, CA 95337, USA (“Lekh”, “we”, “our” or “us”). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and the choices you have.

It applies to:

  • our websites, lekh.app and docs.lekh.app, and our API at api.lekh.app;
  • the Lekh apps for iOS, Android and Mac;
  • the Lekh connector (also called a plugin or MCP server) that you can add to AI assistants such as ChatGPT and Claude.

We call all of these together the “Service”.

2. What we collect

  • Account information. Your name, your email address, and how you sign in: a password (stored only as a one-way hash), Google, Apple, an email sign-in link, or a one-time code sent by email. When you sign in with Google or Apple, we receive your name and email address from that provider.
  • Your content. The boards, folders and library items you create, the images you upload, and your sharing settings, including the email addresses of the people you share boards with.
  • Purchases. Your subscription status and purchase receipts from Stripe (on the web), Apple (App Store) and Google (Google Play). Your card details are held by the payment processor and are never received or stored by Lekh.
  • Usage and analytics. Events describing how the Service is used (for example, signing up, opening the app or opening a board), sent to our product-analytics provider, Mixpanel. Events from the Lekh connector carry your email address and the name of the AI assistant that acted, but never your board content, your search queries or the people you share with.
  • Technical information. Your IP address, and device and browser information, in our server logs and security logs.
  • Forms. When you fill in a form on our website (for example, to contact us), the details you enter, such as your name, email address and, if you give it, your phone number.
  • Optional device permissions. On mobile devices, the apps can ask for these permissions, which are completely optional:
    • Camera: lets you take a picture and add it to a board. You can deny camera access and still use Lekh.
    • Photo gallery: lets you add a picture from your photo gallery to a board. You can deny photo gallery access and still use Lekh.

On mobile devices, boards you keep on the device (not in your Lekh account) stay on that device and are not sent to us.

3. How we use it

  • To provide the Service: store your boards, sync them across your devices, and let you collaborate with other people in real time.
  • To send emails about your account and your boards, such as sign-in links and codes, password resets, and notices that someone has shared a board with you.
  • To process subscriptions and payments.
  • To provide support and answer your questions.
  • To keep the Service secure and to prevent fraud and abuse.
  • To understand how the Service is used and improve it, from usage data.

Lekh does not show advertising, and we do not sell your personal information.

4. AI assistants and the Lekh connector

You can connect an AI assistant, such as ChatGPT or Claude, to your Lekh account. You do this either through Lekh's sign-in and consent screen, which the assistant opens for you, or by creating a personal access token in Lekh and giving it to the assistant.

A connected assistant can do only what the consent screen lists. The consent screen asks for these permissions:

  • See your boards, folders and library items
  • Create, rename, move, delete, duplicate and star boards and folders
  • Read what is on your boards, and see pictures of them
  • Change what is on your boards, and add images to them
  • Share your boards with other people, and revoke shares
  • Browse the shape catalogue and your saved shapes

A personal access token is created either with full access (all of the permissions above) or as read only (seeing your boards, folders and library items, reading your boards, and browsing shapes).

When you ask an assistant to work with a board, the content of that board is sent to the assistant's provider (for example, OpenAI or Anthropic), and the provider handles it under its own privacy policy. Lekh does not receive your conversation with the assistant, and the Lekh connector does not ask for your conversation history.

Lekh records that a connection exists, which assistant it is, which permissions you approved, when it was last used, and the usage events described in section 2.

Your controls. The AI & MCP page in the Lekh app lists the assistants you have connected and the personal access tokens you have created. Disconnecting an assistant there revokes its access within about a minute. Deleting a personal access token revokes it within about a minute. Changing or resetting your password also signs out the assistants you connected through the consent screen.

5. Who we share it with

We share personal information only as described here.

  • Service providers who process information for us, under our instructions:
    • hosting and storage: Amazon Web Services;
    • email delivery: Amazon Web Services;
    • payments: Stripe, Apple and Google;
    • product analytics: Mixpanel;
    • website analytics: Google Tag Manager on lekh.app;
    • internal team notifications: Slack, which receives website form submissions and subscription notices for our team.
  • People you share with. When you share a board, the people you share it with can see it (and edit it, if you allow that), and they may receive an email from us telling them about it. A board shared through a public link can be opened by anyone who has the link.
  • AI assistants you connect, as described in section 4.
  • Legal requirements. When we believe in good faith that disclosure is required by law or legal process, or is needed to protect the rights, property or safety of Lekh, our users or the public.
  • Business transfers. If LEKHAPP LLC is involved in a merger, acquisition or sale of assets, your information may be transferred as part of that transaction, and it will remain subject to this policy.

6. How long we keep it

DataHow long we keep it
Account information and contentFor the life of your account; deleted within 30 days of account deletion
BackupsAge out within 90 days
Analytics eventsUp to 24 months
Server logsUp to 90 days
OAuth authorization codes (used while connecting an AI assistant)10 minutes
AI assistant access tokens1 hour
AI assistant refresh tokens30 days, rotated each time they are used
Personal access tokensUntil you delete them, or until your account is deleted
Pending AI assistant connection requests30 minutes

7. Your choices and rights

  • Access, correction and export. You can see and change your profile in the app. To ask for a copy of your information, or for a correction you cannot make yourself, email info@lekhapp.com.
  • Delete your account. In the Lekh app, open the profile menu, choose My Account, then Delete Account. An account with an active subscription cannot be deleted until the subscription is cancelled; cancel it first through Stripe, the App Store or Google Play. You can also ask us to delete your account by emailing info@lekhapp.com. Deleting your account also disconnects every AI assistant and deletes every personal access token.
  • Withdraw an AI assistant's access at any time on the AI & MCP page (section 4).
  • Device permissions. You can turn camera and photo gallery access on or off at any time in your device's settings.
  • Emails. Any marketing email we send includes an unsubscribe link. Emails needed to run your account, such as sign-in links and share notifications, are not marketing emails.

We will verify your identity before acting on a request, and we will respond within one month. We will not discriminate against you for exercising any of these rights.

California residents (CCPA and CalOPPA)

The California Consumer Privacy Act (CCPA) and the California Online Privacy Protection Act (CalOPPA) require us to disclose the categories of personal information we collect, how we use it, where it comes from and who we share it with. Sections 2 to 5 of this policy set that out. If you are a California resident, you have:

  • The right to know and access: to ask what personal information we have collected, used and shared about you, why, and where it came from, and to receive a copy of it.
  • The right to delete: to ask us to delete the personal information we have collected from you, subject to the exceptions the law allows.
  • The right to correct inaccurate personal information.
  • The right to equal service: we will not discriminate against you for exercising your rights.
  • The right to opt out of sale or sharing: we do not sell your personal information, and we do not share it for targeted ads.

To exercise these rights, email info@lekhapp.com. We do not respond to “Do Not Track” browser signals differently, because we do not track you across other websites.

8. Security

We protect your information with safeguards appropriate to its sensitivity:

  • All traffic between your device and Lekh is encrypted in transit with HTTPS.
  • Passwords are stored only as one-way hashes.
  • AI assistant access tokens are never stored. Refresh tokens are stored only as hashes. Personal access tokens are stored hashed for checking and encrypted for retrieval, with a key kept separately from the data.
  • Card details are handled by the payment processors and never reach Lekh.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If you believe your account has been compromised, change your password, disconnect any assistant you do not recognise, and contact us.

9. Children

Lekh is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has given us personal information, contact us at info@lekhapp.com and we will delete it.

10. Cookies and local storage

The Lekh web app (docs.lekh.app) and API use:

  • _lbsess, a cookie holding a random anonymous session identifier, kept for up to two years. It lets us count visits by people who are not signed in. It is not used to sign you in.
  • _ref, a cookie set only when you arrive through a referral link, recording which link it was, for up to one hour.
  • Local storage in your browser (on the apps, the device's own storage), holding your sign-in state (a refresh token, so you stay signed in), your subscription status, your last export settings, and whether you have seen the AI & MCP page.

Our marketing website, lekh.app, uses Google Tag Manager to measure visits, which may set Google analytics cookies.

You can block or delete cookies and local storage in your browser settings. If you block local storage, the web app cannot keep you signed in.

11. International transfers, changes to this policy, and contact

International transfers. LEKHAPP LLC is based in the United States. Your information is processed in the United States, and our service providers may process it in other countries where they operate. Where the law requires it, we rely on appropriate safeguards for these transfers.

Changes. We may update this policy as the Service changes. When we do, we will change the “Updated” date at the top, and if a change is significant we will tell you through the Service or by email before it takes effect.

Links to other services. This policy does not cover other companies' websites or services, including the AI assistants you connect, which have their own privacy policies.

Contact. If you have a question about this policy or your information, contact us:

  • Email: info@lekhapp.com
  • Mail: LEKHAPP LLC, 2120 Natoma PL, Manteca, CA 95337, USA